. ? + * | { } [ ] ( ) " \
Command Line 1 C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -encodedcommand aQBwAGMAbwBuAGYAaQBnACAALQBhAGwAbAA= RegEx 1 process_name:powershell.exe AND process_cmdline:/[a-zA-Z0-9]+={0,3}/ Command Line 2 C:\Windows\System32\WindowsPowershell\v1.0\powershell -noP -sta -w 1 -enc wBJAE8ATgBUAEEAQgBMAEUALgBQAFMAVgBlAHIAcwBpAG...(total 4285 characters) RegEx 2 process_name:powershell.exe AND process_cmdline:powershell\ -noP\ -sta\ -w\ 1\ \-\enc AND process_cmdline_length:[4280 TO *]